M10:2024: Insufficient Cryptography
Weak, broken, or misused cryptographic algorithms and key management, or encoding mistaken for encryption, leaving protected data effectively exposed.
How it's found
Found through binary and static review that flags broken or weak cryptographic algorithms and inadequate key management in the app.
Standards mapping
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Use of a Broken or Risky Cryptographic Algorithm using testssl.sh to check the live TLS configuration for deprecated protocol versions (SSLv3, TLS 1.0/1.1) and broken ciphers, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 12 dedicated rules for this weakness.
Tools: testssl.sh
Frequently asked questions
What is M10:2024 Insufficient Cryptography?
Weak, broken, or misused cryptographic algorithms and key management, or encoding mistaken for encryption, leaving protected data effectively exposed.
How do you find Insufficient Cryptography?
Found through binary and static review that flags broken or weak cryptographic algorithms and inadequate key management in the app.
Which CWEs map to M10:2024?
M10:2024 maps to CWE-327, CWE-326.
Does TurboPentest test for Insufficient Cryptography?
TurboPentest's automated black-box pentest actively probes for Use of a Broken or Risky Cryptographic Algorithm using testssl.sh to check the live TLS configuration for deprecated protocol versions (SSLv3, TLS 1.0/1.1) and broken ciphers, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 12 dedicated rules for this weakness.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M6:2024: Inadequate Privacy Controls
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest